Troubleshooting DNSSEC Visually
|
|
- Tiffany Terry
- 6 years ago
- Views:
Transcription
1 Troubleshooting DNSSEC Visually Sandia National Laboratories is a multi-program laboratory operated by Sandia Corporation, a wholly owned subsidiary of Lockheed Martin company, for the U.S. Department of Energy s National Nuclear Security Administration under contract DE-AC04-94AL85000.!
2 Outline Motivation Visualizing DNSSEC Future Work
3 Outline Motivation Visualizing DNSSEC Future Work
4 dig ; <<>> DiG P3 <<>> ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 4, ADDITIONAL: 2 ;; QUESTION SECTION: ; IN A ;; ANSWER SECTION: IN CNAME sahp1305.sandia.gov. sahp1305.sandia.gov IN A ;; AUTHORITY SECTION: sandia.gov IN NS NS1.CA.sandia.gov. sandia.gov IN NS NS9.sandia.gov. sandia.gov IN NS NS2.CA.sandia.gov. sandia.gov IN NS NS8.sandia.gov. ;; ADDITIONAL SECTION: NS8.sandia.gov IN A NS9.sandia.gov IN A ;; Query time: 4 msec ;; SERVER: #5353( ) ;; WHEN: Mon Apr 26 12:04: ;; MSG SIZE rcvd: 178 DNS Query and Response
5 DNSSEC Query and Response dig +dnssec ; <<>> DiG P3 <<>> +dnssec ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 4, AUTHORITY: 5, ADDITIONAL: 5 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags: do; udp: 4096 ;; QUESTION SECTION: ; IN A ;; ANSWER SECTION: IN CNAME sahp1305.sandia.gov IN RRSIG CNAME sandia.gov. abcbrkcgw4ejj +HFrxuR/oxygP30Vurs20Aej/F1Bu4ahHsvYNuWVJ94 21hKS8YIu/xbX2UJRrLq390d8OT2vQF9wkVl8IVMViLGdxp1fVTzES+6 XtMHvEMxavuGv9fkHk3Kyt5RNrWwJ1ZquhdsTfzJwTpS9f6u7K5B24Au MOHRI5FscQhy85dfMMCOYn7Xa0mqaM8mgy1k88xy8zSFQ/ htitmgn6hm bd2p/nlynxmxxnjbliqpe9nzupfjk4jbqvjseakphoj+k66cfbn/glyj B3i5wjbHgXSS3XmkBlrTGjpTVRgnj7ARgMNOEV4pj6WHUHkM3k2TF/SK oiry7g== sahp1305.sandia.gov IN A sahp1305.sandia.gov IN RRSIG A sandia.gov. nk85tnprsqaprqyj8kue0km/9mvbcjd0j5xivjtpn0odmcnqec/pypi7 2HyXGJ1MItuQLLP7yDGRubrbFwljkX9DCRvrK1xSGmj +CH2zrFrs30cu te+w24iuak3rdl6nvvpz0pcpjusbphja0g4vmiphbkafyosll7q101jd Ot8Z5FAaEWxCc0rtkKKA3NlmQ64S2RdEYCV1PRO1fvumiCzLE/oJ/vNN nthmmw8f14zv73jxnyuezaklcz5dl3lkyhhbxff0q2z62wr637knh52o 8Gow1gvlQztFDrzAfbYLnd+UGxlGh0/ vaxnrop5jvc1wkk3mjonnhzbk E5pO6Q== 7yYXSg==
6 What happens if something goes wrong? dig +dnssec ; <<>> DiG P3 <<>> +dnssec ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags: do; udp: 4096 ;; QUESTION SECTION: ; IN A ;; Query time: 1085 msec ;; SERVER: #5353( ) ;; WHEN: Mon Apr 26 13:56: ;; MSG SIZE rcvd: 45
7 Manual Troubleshooting (dig) dig ;; ANSWER SECTION: IN A IN RRSIG A medicare.gov. T1/xOmA+nNEpIcS73wF3iB7+fr/ gqhk8hxvl6cnx90juhn3lwub5snwp OWoIC6eBxbjha1+492SQ4VDQYA8wwmlIF9MFRLrrboo25KUsbJfk0The 440l9heY2Wxm74HXBsJclQEbKvNumx6fRPzmad4jK3RjzLzp4barn282 mma= By signature analysis: casey@rome:~$ dig +dnssec medicare.gov dnskey ;; ANSWER SECTION: ZSK id = medicare.gov IN DNSKEY AwEAAcpyc4bhl2jawsXT73t7SzS2QOx6UoOus+cQh7fasvvJ0DZdqrfn KSK id = GeW8YqUtBudvA0phC/ micbkajtecxatopay1zzivicbvf/1f0vay7kjx LDUGIti8DVCksyRoCakgDQsacBcMW6d+0S5CE4lyQm3zoOoIHIsEq8qT Bo81wMO5 DS key tag = medicare.gov IN DNSKEY AwEAAchzoM8KoxpaUTT5Z8jztyH9ETXDT29XS/hjfNgeEWsihRimMok2 k0gvyody1yysfmnzw8nin/pg82bat+s1wptkfgbx8ssc68ufitvfnnxo NK2t0Q2qk87s3cZ/HFJIaAEGGXG0/h8VhZ/DfSQqGQEuAGEfyxhcqj7F => DS references DNSKEY which does ULFVKd7GGBInXIGD3LrtgfaGkUBV2XjG9XH2leSxvXvk29ovNdrLYjWs UFPBzYlQseNBvDYYa8pA99/yYCr1ThGVBl+uRPRcfPhYOEXZ2m9geH9B not exist 82hGflr1xkmKiLjejop10gR0pJW2qVMEG9QZQW0nHEbWEeNO1NA7omtX 0b3ZZq6Jfc0= medicare.gov IN RRSIG DNSKEY medicare.gov. xu/y+q7swm +sjcn9upiz7vuujz03yxx+m2ji89qqmjzse2ehxbnmqazh axlpiwhwftrtptwzcjwo/dfuk7mnkcegc/4l9xogetkcl/lnlaseep2j 3RJPsmFXFLOPGvY2v2Vnik45qJweNmZYse083ouOurAUpCXwpJVUzRa/ plmtt6rdzkm4ht3oc4qtezmakdku/qeicpapqpz0g2g1z8lr86vz+lcp V3tw4TT5Pf92wdRTXzvUG+ZonfyYhD4jNgFKhm6hVreHJmon6hPWo4lK N1HJIZSbV7KDV5GJo5CHFNxYLRmJtfg8YxV4NXqSmOSy8EDgOao1lYbK co+9pa== medicare.gov IN RRSIG DNSKEY medicare.gov. LRmOwpQoqE5ScCDHHkILhPoxBJaMeV0BYMx8M7lXw96F9oI9ub6MWz+u MZkXmyfkld5UKidKQGU1tqLJgIZhOwztRBgYXfTpL7WHP9N0LcfIcs+a n8pyzdup0qeucrahnde7rar3ect6rcjyjswelp+96oabzhquigael6zx 4gs= casey@rome:~$ dig medicare.gov ds ;; ANSWER SECTION: medicare.gov IN DS B998973DAA4C783A7A24B6FC19251FB0CC8064D medicare.gov IN DS FE4FFF98AD71863FC64751C9B3A0D2B2A73622A84DB19E3A08E CDC912F1 medicare.gov IN RRSIG DS gov. Jz14rLZ7r2IaOJHLxDqmIBRvYCH5lPUVh +4kKZit9Rv7wn9oLkcgTXQA rp46sa0l2fzrec6fuedz6sixkkufteq8talbnikpud00yamyydupvg0e YLwPU0XIG4J5axly1FRu1mJ7843ej/ FmmnEfqOq55jzf3Oc+hW18KTFB XpA=
8 DNSKEY Roles DNSKEY roles: ZSK (zone signing key) signs zone data KSK (key signing key) signs only DNSKEY RRset SEP (secure entry point) Typically associated with KSK Resolver must ignore SEP flag Revoked Revoke bit set and self-signed DNSKEY roles don t necessarily follow attributes SEP KSK ZSK Zone data
9 More Automated Methods Other techniques dig +sigchase drill -S Methods are textual, more catered toward advanced users
10 Outline Motivation Visualizing DNSSEC Future Work
11 DNSSEC Visualization A picture is worth one thousand DNS queries. - Loosely adapted from a quote attributed to Chinese proverb
12 Visualization Components Domain name DNSKEY/DS RR DNSKEY attributes SEP Revoke Published Missing Trust anchor NSEC proving non-existence of DS RRs (insecure delegation) Missing
13 Alias dependency Visualization Components Valid Bogus Expired Missing Signature or digest Secure Bogus Insecure Misconfigured Delegation Proof of insecure delegation Sufficient Insufficient
14 The Bottom Line Is there a valid chain of trust from a trust anchor to a node? Secure Bogus Insecure Has the existence of DS RRs been effectively repudiated for insecure delegations?
15 Revisiting medicare.gov: DS RRs exist, but don t match any DNSKEY RR
16 Selective DNSSEC algorithm support (e.g., BIND < 9.6) now insecure instead of bogus
17 Configurable trust anchors and ISC DLV support now secure instead of bogus
18 Linked to root zone, as well as ISC DLV Single DNSKEY, functioning as ZSK, KSK, and SEP
19 Single DNSKEY, functioning as ZSK, KSK, and SEP
20 Both ZSK and KSK function as SEPs, each correspond to a DS (DLV) RR
21 Some authoritative servers missing signatures
22 Multiple signatures across severs; one bogus
23 Multiple signatures across severs; one expired
24 Revoked DNSKEY: revoke bit set and self-signed
25 Expired signature: invalidates NSEC RR covering DS RR, resulting in bogus validation below in the hierarchy
26 Expired signatures in island of security: no effect on security of names
27 Missing signatures
28 Bad KSK rollover; DNSKEY matched with DS/DLV having previous key tag; invalid DNSKEY revocation (missing self-signature)
29 Dependency complexities
30 Server status Consistency DNSKEY RRset Signature Serial PMTU status NSEC3 awareness
31 Outline Motivation Visualizing DNSSEC Future Work
32 Future Work Documentation Visual history of zone for reference, post-mortem analysis Visual representation of server consistency RESTful interface for queries
33 Questions?
Assessing and Improving the Quality of DNSSEC
Assessing and Improving the Quality of DNSSEC Deployment Casey Deccio, Ph.D. Sandia National Laboratories AIMS-4 CAIDA, SDSC, San Diego, CA Feb 9, 2012 Sandia is a multiprogram laboratory operated by Sandia
More informationImplementing DNSSEC with DynDNS and GoDaddy
Implementing DNSSEC with DynDNS and GoDaddy Lawrence E. Hughes Sixscape Communications 27 December 2017 DNSSEC is an IETF standard for adding security to the DNS system, by digitally signing every resource
More informationBIND-USERS and Other Debugging Experiences. Mark Andrews Internet Systems Consortium
BIND-USERS and Other Debugging Experiences Mark Andrews Internet Systems Consortium Mark_Andrews@isc.org http://isc.org BIND-USERS and Other Debugging Experiences We will look at some typical debugging
More information2017 DNSSEC KSK Rollover. DSSEC KSK Rollover
2017 DNSSEC KSK Rollover 2017 Edward Lewis DSSEC KSK Rollover APNIC 44 Edward.Lewis@icann.org FIRST TC September 11, 2017 13 September 2017 DNSSEC Signing vs. Validation DNS Security Extensions Digital
More informationRoot Zone DNSSEC KSK Rollover. DSSEC KSK Rollover
Root Zone DNSSEC KSK Rollover 2017 Edward Lewis DSSEC KSK Rollover ENOG 15 Edward.Lewis@icann.org FIRST TC September 11, 2017 5 June 2018 The Basics This talk is related to the Domain Name System, in particular,
More informationHoda Rohani Anastasios Poulidis Supervisor: Jeroen Scheerder. System and Network Engineering July 2014
Hoda Rohani Anastasios Poulidis Supervisor: Jeroen Scheerder System and Network Engineering July 2014 DNS Main Components Server Side: Authoritative Servers Resolvers (Recursive Resolvers, cache) Client
More informationRSA and ECDSA. Geoff Huston APNIC. #apricot2017
RSA and ECDSA Geoff Huston APNIC It s all about Cryptography Why use Cryptography? Public key cryptography can be used in a number of ways: protecting a session from third party eavesdroppers Encryption
More informationDNS Mark Kosters Carlos Martínez ARIN - LACNIC
DNS Workshop @CaribNOG8 Mark Kosters Carlos Martínez ARIN - LACNIC DNS Refresher and Intro to DNS Security Extension (DNSSEC) Outline Introduction DNSSEC mechanisms to establish authenticity and integrity
More informationDNS security. Karst Koymans & Niels Sijm. Tuesday, September 18, Informatics Institute University of Amsterdam
DNS security Karst Koymans & Niels Sijm Informatics Institute University of Amsterdam Tuesday, September 18, 2012 Karst Koymans & Niels Sijm (UvA) DNS security Tuesday, September 18, 2012 1 / 38 1 Chain
More informationDNS Mark Kosters Carlos Martínez {ARIN, LACNIC} CTO
DNS Workshop @CaribNOG12 Mark Kosters Carlos Martínez {ARIN, LACNIC} CTO DNS Refresher and Intro to DNS Security Extension (DNSSEC) Outline Introduction DNSSEC mechanisms to establish authenticity and
More informationDNSSEC Trust tree: (A) ---dnslab.org. (DS keytag: 9247 dig (DNSKEY keytag. ---org. (DS keytag: d
DNSSEC Trust tree: www.dnslab.org. (A) ---dnslab.org. (DNSKEY keytag: 7308 alg ---dnslab.org. (DNSKEY keytag: 9247 ---dnslab.org. (DS keytag: 9247 dig DNSSEC ---org. (DNSKEY keytag: 24209 a Domain Name
More informationTable of Contents. DNS security. Alternative DNS security mechanism. DNSSEC specification. The long (and winding) road to the DNSSEC specification
Table of Contents DNS security Karst Koymans Informatics Institute University of Amsterdam (version 1.19, 2011/09/27 14:18:11) Friday, September 23, 2011 The long (and winding) road to the DNSSEC specification
More informationA Look at RFC 8145 Trust Anchor Signaling for the 2017 KSK Rollover
A Look at RFC 8145 Trust Anchor Signaling for the 2017 KSK Rollover Duane Wessels DNS-OARC 26 San Jose, CA September 29, 2017 Background 2 2017 Root Zone KSK Rollover October 11, 2017! Root zone DNSKEY
More informationA Case for Comprehensive DNSSEC Monitoring and Analysis Tools
A Case for Comprehensive DNSSEC Monitoring and Analysis Tools Casey Deccio Sandia National Laboratories ctdecci@sandia.gov Jeff Sedayao and Krishna Kant Intel Corporation {jeff.sedayao,krishna.kant}@intel.com
More informationAlgorithm for DNSSEC Trusted Key Rollover
Algorithm for DNSSEC Trusted Key Rollover Gilles Guette, Bernard Cousin, and David Fort IRISA, Campus de Beaulieu, 35042 Rennes CEDEX, FRANCE {gilles.guette, bernard.cousin, david.fort}@irisa.fr Abstract.
More informationDENIC DNSSEC Testbed Software support for DNSSEC Ralf Weber
DENIC DNSSEC Testbed Software support for DNSSEC Ralf Weber (ralf.weber@nominum.com) Who is Nominum? Mission Product Leadership Industry Expertise Deliver the Trusted Internet Experience Strategic Partners:
More informationTable of Contents. DNS security basics. What DNSSEC has to offer. In what sense is DNS insecure? Why DNS needs to be secured.
Table of Contents DNS security basics The basics Karst Koymans (with Niels Sijm) Informatics Institute University of Amsterdam (version 2.3, 2013/09/13 11:46:36) Tuesday, Sep 17, 2013 Why DNS needs to
More informationExpires: June 16, 2004 VeriSign R. Austein ISC D. Massey USC/ISI S. Rose NIST December 17, 2003
DNS Extensions Internet-Draft Expires: June 16, 2004 R. Arends Telematica Instituut M. Larson VeriSign R. Austein ISC D. Massey USC/ISI S. Rose NIST December 17, 2003 Protocol Modifications for the DNS
More informationHands-on DNSSEC with DNSViz. Casey Deccio, Verisign Labs RIPE 72, Copenhagen May 23, 2016
Hands-on DNSSEC with DNSViz Casey Deccio, Verisign Labs RIPE 72, Copenhagen May 23, 2016 Preparation Demo and exercises available at: http://dnsviz.net/demo/ Includes links to the following: VirtualBox
More informationLab 6 Implementing DNSSEC
Lab 6 Implementing DNSSEC Objective: Deploy DNSSEC-signed zones. Background DNSSEC (or DNS Security Extensions) provide security to the zone files. Note: In the steps below, we are using myzone.net - our
More informationDNS/DNSSEC Workshop. In Collaboration with APNIC and HKIRC Hong Kong. Champika Wijayatunga Regional Security Engagement Manager Asia Pacific
DNS/DNSSEC Workshop In Collaboration with APNIC and HKIRC Hong Kong Champika Wijayatunga Regional Security Engagement Manager Asia Pacific 22-24 January 2018 1 DNSSEC 2 2 DNS: Data Flow Zone administrator
More informationAn Overview of DNSSEC. Cesar Diaz! lacnic.net!
An Overview of DNSSEC Cesar Diaz! cesar@ lacnic.net! 1 DNSSEC??? The DNS Security Extension (DNS SEC) attach special kind of information called criptographic signatures to the queries and response that
More informationNetwork Working Group
Network Working Group R. Arends Request for Comments: 4035 Telematica Instituut Obsoletes: 2535, 3008, 3090, 3445, 3655, 3658, R. Austein 3755, 3757, 3845 ISC Updates: 1034, 1035, 2136, 2181, 2308, 3225,
More informationMeasuring DNS Vulnerabilities and DNSSEC Challenges from an Irish Perspective. SATIN Conference, NPL, London, 04 th April 2011
Measuring DNS Vulnerabilities and DNSSEC Challenges from an Irish Perspective SATIN Conference, NPL, London, 04 th April 2011 Introduction Billy Glynn (working with IEDR for circa. 10 years) IEDR operate
More informationDNSSEC operational experiences and recommendations. Antti Ristimäki, CSC/Funet
DNSSEC operational experiences and recommendations Antti Ristimäki, CSC/Funet Agenda Funet DNSSEC status A short DNSSEC tutorial Zone signing considerations Private key security Network layer impacts Monitoring
More information3. The DNSSEC Primer. Data Integrity (hashes) Authenticated Denial of Existence (NSEC,
3. The DNSSEC Primer Authentication (keys, signatures) Data Integrity (hashes) Chain of Trust (root zone, when signed) Authenticated Denial of Existence (NSEC, NSEC3) DNS Authoritative ROOT SERVERS TLD
More informationDNSSEC for ISPs workshop João Damas
DNSSEC for ISPs workshop João Damas (joao@isc.org) 1 Outline of workshop Brief intro to DNSSEC Overview of zone signing DNSSEC validation trust anchors validation impact of enabling validation debugging
More informationDNSSEC HOWTO. A Tutorial in Disguise. Olaf Kolkman, RIPE NCC Published September, $Revision: $
DNSSEC HOWTO A Tutorial in Disguise. Olaf Kolkman, RIPE NCC Published September, 2004 $Revision: 1.4.4.8 $ For review only, do not redistribute. DNSSEC HOWTO A Tutorial in Disguise. This
More informationIs your DNS server up-to-date? Pieter Lexis Senior PowerDNS Engineer April 22 nd 2018
lieter_ PowerDNS pieterlexis PowerDNS Is your DNS server up-to-date? Pieter Lexis Senior PowerDNS Engineer April 22 nd 2018 1 What s all this about? A DNS recap What is EDNS? Issues with EDNS on the internet
More informationDNSSEC in Switzerland 2 nd DENIC Testbed Meeting
DNSSEC in Switzerland 2 nd DENIC Testbed Meeting Frankfurt, 26. January 2010 Samuel Benz samuel.benz@switch.ch About SWITCH The SWITCH foundation operates the national research network since 1987 SWITCH
More informationARIN Support for DNSSEC and RPKI. ION San Diego 11 December 2012 Pete Toscano, ARIN
ARIN Support for DNSSEC and ION San Diego 11 December 2012 Pete Toscano, ARIN 2 DNS and BGP They have been around for a long time. DNS: 1982 BGP: 1989 They are not very secure. Methods for securing them
More informationTesting IPv6 address records in the DNS root
Testing IPv6 address records in the DNS root February 2007 Geoff Huston Chief Scientist APNIC Priming a DNS name server 1. Take the provided root hints file 2. Generate a DNS query for resource records
More informationExpires: November 15, 2004 VeriSign R. Austein ISC D. Massey USC/ISI S. Rose NIST May 17, 2004
DNS Extensions Internet-Draft Expires: November 15, 2004 R. Arends Telematica Instituut M. Larson VeriSign R. Austein ISC D. Massey USC/ISI S. Rose NIST May 17, 2004 Protocol Modifications for the DNS
More informationScott Rose, NIST Winter JointTechs Meeting Jan 30, 2011 Clemson University
Scott Rose, NIST scottr@nist.gov 2011 Winter JointTechs Meeting Jan 30, 2011 Clemson University Special Thanks to RIPE NCC who provided the base slides for this tutorial. DNS is not secure Known vulnerabilities
More informationThe State and Challenges of the DNSSEC Deployment. Eric Osterweil Michael Ryan Dan Massey Lixia Zhang
The State and Challenges of the DNSSEC Deployment Eric Osterweil Michael Ryan Dan Massey Lixia Zhang 1 Monitoring Shows What s Working and What needs Work DNS operations must already deal with widespread
More informationDefeating DNS Amplification Attacks. UKNOF Manchester Central, UK January Ralf Weber Senior Infrastructure Architect
Defeating DNS Amplification Attacks UKNOF Manchester Central, UK January 21 2014 Ralf Weber Senior Infrastructure Architect History of DNS Amplification DNS amplification attacks aren't new Periodically
More informationTyre Kicking the DNS. Testing Transport Considerations of Rolling Roots. Geoff Huston APNIC
Tyre Kicking the DNS Testing Transport Considerations of Rolling Roots Geoff Huston APNIC Five Years Ago The US KSK Repository The Amsterdam KSK Repository George Michaelson Five Years Ago Five Years Ago
More informationRoot Servers. Root hints file come in many names (db.cache, named.root, named.cache, named.ca) See root-servers.org for more detail
What is DNS? Systems to convert domain names into ip addresses: For an instance; www.tashicell.com 118.103.136.66 Reverse: 118.103.136.66 www.tashicell.com DNS Hierarchy Root Servers The top of the DNS
More informationECE 435 Network Engineering Lecture 7
ECE 435 Network Engineering Lecture 7 Vince Weaver http://web.eece.maine.edu/~vweaver vincent.weaver@maine.edu 25 September 2018 HW#3 was Posted Announcements 1 HW#2 Review C code will be discussed next
More informationDNSSEC. Lutz Donnerhacke. db089309: 1c1c 6311 ef09 d819 e029 65be bfb6 c9cb dig +dnssec e164.arpa. naptr
DNSSEC Lutz Donnerhacke db089309: 1c1c 6311 ef09 d819 e029 65be bfb6 c9cb dig +dnssec 1.6.5.3.7.5.1.4.6.3.9.4.e164.arpa. naptr 1 A protocol from better times An ancient protocol People were friendly and
More informationDNSSEC at ORNL. Paige Stafford Joint Techs Conference, Fairbanks July 2011
DNSSEC at ORNL Paige Stafford Joint Techs Conference, Fairbanks July 2011 Outline Background Brief review of DNSSEC ORNL before DNSSEC was implemented Implementation experience Signer appliance Validation
More informationRoot Zone DNSSEC KSK Rollover
Root Zone DNSSEC KSK Rollover 51 51 KSK Rollover: An Overview ICANN is in the process of performing a Root Zone DNS Security Extensions (DNSSEC) Key Signing Key (KSK) rollover The Root Zone DNSSEC Key
More informationDNSSEC HOWTO, a tutorial in disguise
DNSSEC HOWTO, a tutorial in disguise Olaf Kolkman Version 1.8.2 (svn: 96) March 30, 2007 Contents Download the most recent version of the PDF version here: http://www.nlnetlabs.nl/dnssec howto/dnssec howto.pdf
More informationNetwork Working Group. Category: Informational November 2007
Network Working Group S. Weiler Request for Comments: 5074 SPARTA, Inc. Category: Informational November 2007 Status of This Memo DNSSEC Lookaside Validation (DLV) This memo provides information for the
More informationRolling the Root KSK. Geoff Huston. APNIC Labs. September 2017
Rolling the Root KSK Geoff Huston APNIC Labs September 2017 Will this break the Internet? Why? If we stuff up this trust anchor key roll then resolvers that perform DNSSEC validation will fail to provide
More informationThe impact of DNSSEC on k.root-servers.net and ns-pri.ripe.net
The impact of DNSSEC on k.root-servers.net and ns-pri.ripe.net Olaf M. Kolkman Question What would be the immediate and initial effect on memory, CPU and bandwidth resources if we were to deploy DNSSEC
More informationAuthoritative-only server & TSIG
Authoritative-only server & TSIG cctld workshop Apia, Samoa,20 23 June 2006 Andy Linton (Materials by Alain Aina) Different type of servers Several types of name servers Authoritative servers master (primary)
More informationDNSSEC Validators Requirements
DNSSEC Validators Requirements draft-mglt-dnsop-dnssec-validator-requirements-05 Migault, Lewis, York IETF99 ToC Time Requirements Trust Anchor Requirements Bootstrapping / configuration TA Datastore Interaction
More informationDNSSEC deployment. Phil Regnauld Hervey Allen
DNSSEC deployment Phil Regnauld Hervey Allen Overview We will talk about: the problems that DNSSEC addresses the protocol and implementations the practical problems tied to real-world deployment We will
More informationSome DNSSEC thoughts. DNSOPS.JP BOF Interop Japan Geoff Huston Chief Scientist, APNIC June 2007
Some DNSSEC thoughts DNSOPS.JP BOF Interop Japan 2007 Geoff Huston Chief Scientist, APNIC June 2007 The DNS is a miracle! You send out a question into the net And an answer comes back! Somehow But WHO
More informationDNS over IPv6 - A Study in Fragmentation
DNS over IPv6 - A Study in Fragmentation DNS OARC, September 2017 Geoff Huston, Joao Damas APNIC Labs What happens to a large DNS response? (Where large is > 1280 octets) What happens to a large DNS response?
More informationQualita've DNS Measurement Perspec'ves
Qualita've DNS Measurement Perspec'ves Casey Deccio Sandia Na/onal Laboratories ISC/CAIDA Data Collabora/on Workshop Oct 22, 2012 Sandia National Laboratories is a multi-program laboratory managed and
More informationDomain Name System Security
Domain Name System Security T-110.4100 Tietokoneverkot September 2010 Bengt Sahlin 2011/09/27 Bengt Sahlin 1 Objectives Provide DNS basics, essential for understanding DNS security
More information12 DNS Security Extensions DNS resolution via recursive nameserver DNS request/response format Simple DNS cache poisoning The Dan Kaminsky DNS
12 DNS Security Extensions DNS resolution via recursive nameserver DNS request/response format Simple DNS cache poisoning The Dan Kaminsky DNS vulnerability DNS root servers DNSSEC chain of trust DNSSEC
More informationMonitoring DNSSEC. Martin Leucht Julien Nyczak Supervisor: Rick van Rein
Monitoring DNSSEC Martin Leucht Julien Nyczak Supervisor: Rick van Rein System and Network Engineering 2015 Introduction DNSSEC becomes more and more popular
More informationWorst Current Practice. Lutz Donnerhacke IKS GmbH
Worst Current Practice Lutz Donnerhacke IKS GmbH Worst Current Practice Not a talk about simple bugs Too many WTFs to talk about Sometimes instructive anyway SEOS: IPv6 packets crash Ether Channels: Card
More informationGDS Resource Record: Generalization of the Delegation Signer Model
GDS Resource Record: Generalization of the Delegation Signer Model Gilles Guette, Bernard Cousin, and David Fort IRISA, Campus de Beaulieu, 35042 Rennes CEDEX, France {gilles.guette, bernard.cousin, david.fort}@irisa.fr
More informationCNAME-based Redirection Design Notes
CNAME-based Redirection Design Notes When we configure a redirect type of local-zone or access-control action, we might want to specify a CNAME as the action data, whose canonical name is managed by an
More informationInternet Engineering. DNS Message Format. Contents. Robert Elz.
Internet Engineering 241-461 Robert Elz kre@munnari.oz.au kre@coe.psu.ac.th http://fivedots.coe.psu.ac.th/~kre Contents The Domain Name System The DNS Database DNS Protocols DNS Message Formats ueries
More informationpage 1 Plain Old DNS WACREN, DNS/DNSSEC Regional Workshop Ouagadougou, October 2016
page 1 Plain Old DNS WACREN, DNS/DNSSEC Regional Workshop Ouagadougou, 10-14 October 2016 page 2 IP: Identifiers on the Internet The fundamental identifier on the internet is an IP address. Each host connected
More informationDNSSEC for ISPs workshop.! João Damas
DNSSEC for ISPs workshop!!! João Damas (joao@isc.org) 1 Outline of workshop Brief intro to DNSSEC (30 ) Overview of zone signing (30 ) DNSSEC validation (60 ) trust anchors validation impact of enabling
More informationDNS SECurity Extensions technical overview
The EURid Insights series aims to analyse specific aspects of the domainname environment. The reports are based on surveys, studies and research developed by EURid in cooperation with industry experts
More informationSession J9: DNSSEC and DNS Security
Session J9 and Security InfoSec World 2008 Session J9: and Security Steve Pinkham, Maven Security Consulting What is? slide 2 Easy answer: Stands for Domain Name System System for converting names to/from
More informationDocumentation. Name Server Predelegation Check
Name Server Predelegation Check Doc. version: 1.4.1 Doc. status: Final Doc. date: 01.12.2015 Doc. name: Name Server Predelegation Check- -DNS Services-V1.4.1-2015-12-01 Copyright 2015 DENIC eg Imprint
More informationDomain Name System (DNS) Session-1: Fundamentals. Joe Abley AfNOG Workshop, AIS 2017, Nairobi
Domain Name System (DNS) Session-1: Fundamentals Joe Abley AfNOG Workshop, AIS 2017, Nairobi Computers use IP addresses. Why do we need names? Names are easier for people to remember Computers may be moved
More informationA Security Evaluation of DNSSEC with NSEC Review
A Security Evaluation of DNSSEC with NSEC Review Network Security Instructor:Dr. Shishir Nagaraja Submitted By: Jyoti Leeka November 16, 2011 1 Introduction to the topic and the reason for the topic being
More informationUnderstanding and Deploying DNSSEC. Champika Wijayatunga SANOG29 - Pakistan Jan 2017
Understanding and Deploying DNSSEC Champika Wijayatunga SANOG29 - Pakistan Jan 2017 Agenda 1 2 3 Background Why DNSSEC? How it Works? 4 5 Signatures and Key Rollovers DNSSEC Demo 2 3 Background DNS in
More informationDomain Name System Security
Slide title 70 pt APITALS Domain Name System Security e subtitle um 30 pt Bengt Sahlin Ericsson Research NomadicLab Bengt.Sahlin@ericsson.com Objectives Provide DNS basics, essential for understanding
More informationInternet Engineering Task Force (IETF) Request for Comments: ISSN: K. Fujiwara JPRS December 2015
Internet Engineering Task Force (IETF) Request for Comments: 7719 Category: Informational ISSN: 2070-1721 P. Hoffman ICANN A. Sullivan Dyn K. Fujiwara JPRS December 2015 DNS Terminology Abstract The DNS
More informationCS 356 Using Cryptographic Tools to Secure the Domain Name System (DNS) Spring 2017
CS 356 Using Cryptographic Tools to Secure the Domain Name System (DNS) Spring 2017 Background Motivation Overview Network Infrastructure Security DNS and DNS Vulnerabilities The DNS Security Extensions
More informationDNSSEC at Penn. Shumon Huque University of Pennsylvania ESCC/Internet2 Joint Techs Conference July 20th 2009
DNSSEC at Penn Shumon Huque University of Pennsylvania ESCC/Internet2 Joint Techs Conference July 20th 2009 1 DNSSEC at a glance DNS Security Extensions A system to verify the authenticity of DNS data
More information2017 DNSSEC KSK Rollover. Guillermo Cicileo LACNIC March 22, 2017
2017 DNSSEC KSK Rollover Guillermo Cicileo LACNIC March 22, 2017 Purpose of this Talk 1 2 3 To publicize the new Root Zone DNSSEC KSK Provide status, upcoming events, and contact information Provide helpful
More informationDNSSEC All You Need To Know To Get Started
DNSSEC All You Need To Know To Get Started Olaf M. Kolkman RIPE NCC A Semi Technical Introduction Why do we need DNSSEC What does DNSSEC provide How does DNSSEC work Question: www.ripe.net A Reminder:
More informationSecSpider: Distributed DNSSEC Monitoring and Key Learning
SecSpider: Distributed DNSSEC Monitoring and Key Learning Eric Osterweil UCLA Joint work with Dan Massey and Lixia Zhang Colorado State University & UCLA 1 Who is Deploying DNSSEC? Monitoring Started From
More informationThat KSK Roll. Geoff Huston APNIC Labs
That KSK Roll Geoff Huston APNIC Labs The DNS may look simple But with the DNS, looks are very deceiving So lets talk DNSSEC DNSSEC introduces digital signatures into the DNS It allows a DNS resolver to
More informationTHE BRUTAL WORLD OF DNSSEC
THE BRUTAL WORLD OF DNSSEC Patrik Fältström Head of Technology Netnod 1 Security Issues with DNS Zone Administrator Bad Data False Master Caching Resolver Zonefile Master Slave slave slave False Cache
More informationRolling the Root. Geoff Huston APNIC Labs March 2016
Rolling the Root Geoff Huston APNIC Labs March 2016 Use of DNSSEC Validation in Today s Internet Why is this relevant? Because the root zone managers are preparing to roll the DNS Root Zone Key Signing
More informationDNSSec Operation Manual for the.cz and e164.arpa Registers
DNSSec Operation Manual for the.cz and 0.2.4.e164.arpa Registers version 1.9., valid since 1 January 2010 Introduction This material lays out operational rules that govern the work of the CZ.NIC association
More informationStep by step DNSSEC deployment in.se. Anne-Marie Eklund Löwinder Quality & Security
Step by step DNSSEC deployment in.se Anne-Marie Eklund Löwinder Quality & Security Manager,.SE amel@iis.se @amelsec www.iis.se Timeline 2005 signing of the.se zone. 2006 allowing DS records from friendly
More informationDNSSEC DNS SECURITY EXTENSIONS INTRODUCTION TO DNSSEC FOR SECURING DNS QUERIES AND INFORMATION
DNSSEC DNS SECURITY EXTENSIONS INTRODUCTION TO DNSSEC FOR SECURING DNS QUERIES AND INFORMATION Peter R. Egli 1/10 Contents 1. Security Problems of DNS 2. Solutions for securing DNS 3. Security with DNSSEC
More informationMulti Provider DNSSEC draft-huque-dnsop-multi-provider-dnssec-02. Shumon Huque March 22 nd 2018 DNSOP Working Group, IETF101, London, U.K.
Multi Provider DNSSEC draft-huque-dnsop-multi-provider-dnssec-02 Shumon Huque March 22 nd 2018 DNSOP Working Group, IETF101, London, U.K. Note to the DNS Camel* This document does not propose any new extensions
More informationInternet-Draft Intended status: Experimental March 28, 2014 Expires: September 29, 2014
Network Working Group M. Andrews Internet-Draft ISC Intended status: Experimental March 28, 2014 Expires: September 29, 2014 Abstract EDNS EXPIRE OPTION draft-andrews-dnsext-expire-04 This document specifies
More informationDNSSEC. Training Course
DNSSEC Training Course Training Services RIPE NCC March 2017 Schedule 09:00-09:30 11:00-11:15 13:00-14:00 15:30-15:45 17:30 Coffee, Tea Break Lunch Break End 2 Introduction Name Number on the list Experience
More informationDNSSEC KSK-2010 Trust Anchor Signal Analysis
DNSSEC KSK-2010 Trust Anchor Signal Analysis MAPRG @ IETF102 1 Overview Background: DNSSEC KSK rollover and plan Problems with the KSK rollover Case study analysis: difficulty in identifying old Trust
More informationDomain Name System Security
Domain Name System Security T-110.4100 Tietokoneverkot October 2008 Bengt Sahlin 2008/10/02 Bengt Sahlin 1 Objectives Provide DNS basics, essential for understanding DNS security
More informationNetwork Working Group Request for Comments: 5155 Category: Standards Track Nominet D. Blacka VeriSign, Inc. March 2008
Network Working Group Request for Comments: 5155 Category: Standards Track B. Laurie G. Sisson R. Arends Nominet D. Blacka VeriSign, Inc. March 2008 DNS Security (DNSSEC) Hashed Authenticated Denial of
More informationKeeping DNS parents and children in sync at Internet Speed! Ólafur Guðmundsson
Keeping DNS parents and children in sync at Internet Speed! Ólafur Guðmundsson olafur@cloudflare.com How long does it take to? Post a new selfie on Facebook and all your friends to be notified few seconds
More informationMigrating an OpenDNSSEC signer (February 2016)
Migrating an OpenDNSSEC signer (February 2016) Contributors David Njuki Amreesh Phokeer Logan Velvindron Alain Aina Email david.njuki@afrinic.net amreesh@afrinic.net logan@afrinic.net aalain@trstech.net
More informationCreating Your Virtual Data Center
NET201 Creating Your Virtual Data Center VPC Fundamentals and Connectivity Options Becky Weiss, Principal Engineer, EC2 Networking October 2015 2015, Amazon Web Services, Inc. or its Affiliates. All rights
More informationSecuring Domain Name Resolution with DNSSEC
White Paper Securing Domain Name Resolution with DNSSEC diamondip.com by Timothy Rooney Product management director BT Diamond IP Resolution with DNSSEC Introduction By Tim Rooney, Director, Product Management
More informationHow to Enable Internet for Guest Virtual Machine using Datacard Tata Photon.
How to Enable Internet for Guest Virtual Machine using Datacard Tata Photon. Table of Contents 1) Host, Guest and VBox version.... 2 2) Check your current Host and add 3 rd Adapter to Host windows... 3
More informationFortiNAC SRV Records on Production DNS
FortiNAC SRV Records on Production DNS Version: 8.x Date: 09/10/2018 Rev: B FORTINET DOCUMENT LIBRARY http://docs.fortinet.com FORTINET VIDEO GUIDE http://video.fortinet.com FORTINET KNOWLEDGE BASE http://kb.fortinet.com
More informationPreparation Test AAAA and EDNS0 support Share Your Results Results Reported Testing Period
Testing Recursive Name Servers for IPv6 and EDNS0 Support SAC 017 15 March 2007 Preparation Test AAAA and EDNS0 support Share Your Results Results Reported Testing Period Background The DNS Root Server
More informationEDNS Compliance. Mark Andrews
EDNS Compliance Mark Andrews marka@isc.org DataSets Root and TLD servers Alexa Top 1000 Alexa Bottom 1000 of Top 1Million GOV servers from Alexa Top 1Million AU servers from Alexa Top 1Million Methodology
More information6.033 Computer System Engineering
MIT OpenCourseWare http://ocw.mit.edu 6.033 Computer System Engineering Spring 2009 For information about citing these materials or our Terms of Use, visit: http://ocw.mit.edu/terms. M.I.T. DEPARTMENT
More informationToward Unspoofable Network Identifiers. CS 585 Fall 2009
Toward Unspoofable Network Identifiers CS 585 Fall 2009 The Problem DNS Spoofing Attacks (e.g., Kaminsky) At link (Ethernet) and IP layers, either: Software sets the source address in the packet, or Software
More informationENUM Dialing on Cisco Expressway
ENUM Dialing on Cisco Expressway Deployment Guide Cisco Expressway X8.2 D15064.02 June 2014 Contents Introduction 3 Configuring the Expressway 4 Configuring an ENUM zone and search rule 4 Configuring the
More informationICANN DNSSEC Workshop Comcast s Operational Experiences 14 March 2012
ICANN DNSSEC Workshop Comcast s Operational Experiences 14 March 2012 NATIONAL ENGINEERING & TECHNICAL OPERATIONS DNSSEC Deployment Status We began working on this in 2008 (see Bmeline) We completed our
More information22/06/ :37 DNS COMPLIANCE. Fred Baker Internet Systems Consortium
DNS COMPLIANCE Fred Baker Internet Systems Consortium Background - 2014 ISC was in the process of adding DNS COOKIE (RFC 7873) to BIND and we wanted to see how many servers would mishandle DNS COOKIE options
More informationSome Internet exploits target name resolution servers. DNSSEC uses cryptography to protect the name resolution
SYSADMIN DNSSEC Sergey Ilin, Fotolia Trusted name resolution with DNSSEC CHAIN OF TRUST Some Internet exploits target name resolution servers. DNSSEC uses cryptography to protect the name resolution service.
More information